Prosper Data Privacy and HIPAA Overview for Clients
Recent national headlines have highlighted proposals to collect and centralize private health data from autistic individuals—all in the name of “explaining” or “solving” autism. These discussions have sparked understandable concern throughout the autistic community. At Prosper Health, we want to be absolutely clear about where we stand and what you can expect from us:
We Reject the Framing of Autism as a Disease
Autism is not an epidemic. It is a natural and valuable part of human diversity—a developmental difference, not a defect to be “cured” or “corrected.” When autistic people receive respect, support, and understanding, they flourish. Any effort to “root out” or “track” autism with suspicion is not only scientifically baseless—it is deeply harmful.
Your Data Belongs to You
Prosper Health takes your data and privacy extremely seriously. We adhere to HIPAA and the strictest standards of confidentiality.
We will never share your protected health information unless absolutely necessary or required by law—and even then, only with the utmost care and transparency. We do share necessary data with insurance partners, but they are also bound to strict privacy and confidentiality regulations via HIPAA.
Our commitment to data privacy is not just about legal compliance, it is about respecting our clients.
Legal Protections Remain Strong
Despite recent proposals and media attention, the NIH does not have the legal authority to collect your identifiable insurance claims or medical records without your clear consent. By law, insurance companies and healthcare providers cannot share identifiable health information without your explicit consent. Even when data is de-identified and used for research, legal requirements are in place so it cannot be traced back to any individual.
Any data sharing—by Prosper or anyone else—must comply with HIPAA and other strict federal regulations.
Your Voice Matters
It’s reasonable to be concerned. We encourage you to ask your healthcare providers—including us—about their data policies. Review the privacy settings on any health apps or devices you use. Advocate for your rights and for the broader autistic community—online, with your elected officials, and in your everyday life.
At Prosper Health, we will always stand with you: affirming neurodiversity, protecting your privacy, and working for a future where autistic adults are respected, supported, and empowered.We are here to support you now and with whatever may lie ahead. Please see below for a list of frequently asked questions related to data policies and our practices. If you have any further questions about how your data is handled—or if you just want to talk to someone—please reach out to our team at help@prosperhealth.io.
Data Privacy FAQs
How does Prosper Health protect my data and information?
We know that privacy and data security are top concerns, and we want to be transparent about how we protect your information. At Prosper Health, we follow strict HIPAA guidelines to ensure your data is secure, confidential, and only shared when absolutely necessary. We do not sell or share your data for commercial or political purposes, and only authorized professionals involved in your care have access to your records.
There are very limited situations where we may be required to share information, such as legally valid court orders or if there is an immediate safety risk. If you use insurance, we share only the minimum necessary details—such as diagnosis and billing codes—to process claims, and insurers are also required to protect your data under HIPAA.
To be clear:
- We do not share your session notes, full medical history, or sensitive personal information with any government agency unless required by law.
- We only share the minimum necessary data with insurance companies to process insurance claims.
- We follow strict privacy policies and, in the rare event that someone other than your insurance requests information, we will notify you whenever possible.
Your privacy is essential to us, and we are committed to protecting your data with the highest security standards. If you have any concerns or questions, please don’t hesitate to reach out.
Who does Prosper Health share my data with?
Prosper Health does not share your data with anyone unless it is absolutely necessary to your care or legally required. We are fully compliant with the Health Insurance Portability and Accountability Act (HIPAA), which sets strict rules on how healthcare data is handled.
Under HIPAA, we are required to share certain health information in very limited circumstances:
- If you give us explicit permission – We will only share your records with another provider, entity, or individual if you request and authorize it.
- For treatment and care coordination – If necessary, we may share relevant information with your other healthcare providers to support your care. We will never do this without your consent.
- Your insurance company - If you are using insurance to pay for services, we submit certain information to your insurer for claims processing. While we do share limited necessary information with insurance (more below), insurance companies must also comply with HIPAA regulations.
- To comply with a legally valid request – This includes:
- Court orders – If a court issues a legally binding order, we may be required to share specific information. However, we will only disclose the minimum necessary data and will notify you if legally allowed.
- Serious safety risks – If there is an imminent risk of harm to you or someone else, we may be required to share limited information with emergency responders to ensure safety.
Outside of these specific legal situations, your information remains fully private and secure.
What information does Prosper Health share with my insurance company?
If you are using insurance to pay for services, we must submit certain information to your insurer for claims processing. This typically includes:
- Diagnosis codes – These are required by insurance to determine coverage.
- Service details – This includes the type of service (e.g., therapy session, evaluation) and session dates.
- Billing codes (CPT codes) – These codes indicate the type of service provided and the time spent.
- Minimal provider notes (only when required by the insurer) – In some cases, insurers may request brief documentation to verify the necessity of care. However, we do not share full session notes or detailed records unless explicitly required and authorized by you.
Importantly, insurance companies must also comply with HIPAA. If you have concerns about how your insurance company uses your data, we recommend reviewing their privacy policy.
What does Prosper Health do to keep data secure?
At Prosper Health, we use industry-leading security practices to keep your data safe. This includes:
- HIPAA compliance – We follow strict federal guidelines to protect your health information.
- Encryption – Your data is encrypted both in transit and at rest, meaning it’s secure whether being sent or stored.
- Limited access – Only authorized healthcare professionals involved in your care can access your records.
- Secure storage – We use secure cloud-based systems that are regularly audited to ensure compliance with healthcare privacy laws. We continuously monitor and update our security protocols to keep your information protected against unauthorized access.
Could the government access my therapy records or diagnosis information?
Your therapy records and diagnosis information are private and protected by HIPAA, which strictly limits who can access them. The government—including agencies like the NIH—cannot access your identifiable health information without your explicit consent, except in extremely rare and specific legal situations (such as a valid court order or a law passed by Congress).
At Prosper Health, we do not share your records with government agencies, law enforcement, or political entities unless we are legally required to do so—and only after all privacy safeguards have been reviewed. To date, Prosper Health has never shared any client records with government entities.
Can I request a full copy of all my records?
Yes, under HIPAA, you have the right to request and receive a copy of your medical records, including session notes, diagnosis information, and most other data we maintain about your care (outside of a few, select assessment forms) If you’d like to request your records, simply reach out to our support team, and we’ll guide you through the process. There may be a brief processing time, but we will ensure you receive your records in a secure and timely manner.
Can I ask Prosper Health to delete my records if I no longer want them stored?
Healthcare providers are required by law to retain medical records for a certain period, typically ranging from 5 to 10 years depending on state laws. However, if you no longer wish to receive services from Prosper Health, we can archive your records and restrict access. After the required retention period, we will securely delete them. If you have specific concerns about your data, we are happy to discuss your options.